
Don’t switch conference rooms during your meetings via Zoom or Google Meet, an expert advises.
North Korean hackers are exploiting various methods to trick their victims into downloading malware. In their latest attempt, hackers imitate venture capitalists in a Zoom video call, suggesting that there’s an audio issue.
During the call, cybercriminals pretend that they can’t hear a user, and send a link to install a patch to fix the audio or video. However, in reality, the “patch” or the “fix” is malware.
“They exploit human psychology – you think you're meeting with important venture capitalists and rush to fix the audio, causing you to be less careful than you usually are. Once you install the patch, you're rekt,” explained Nick Bah, a member of Security Alliance, in a post on X last week.
Bah added that the hacker group behind the recent attack had stolen tens of millions of dollars and that other groups were copying their tactics.
“If anybody ever tells you to switch conference rooms, create your own secure Google Meet room and direct them there, instead of using whatever they suggest,” he advised.
Having audio issues on your Zoom call? That's not a VC, it's North Korean hackers.
undefined Nick Bax.eth (@bax1337) March 11, 2025
Fortunately, this founder realized what was going on.
The call starts with a few undefinedVCsundefined on the call. They send messages in the chat saying they can't hear your audio, or suggesting there's an… pic.twitter.com/ZnW8Mtof4F
North Korean hackers are increasingly exploiting methods to trick users into downloading malware.
Besides imitating investors at meetings, they often create fake identities and pose as job seekers trying to infiltrate US companies as programmers. The money earned is fed back to North Korea to support the regime.
Last month, researchers at ESET detailed how North Korean hackers use various job-hunting platforms posing as recruiters to trick users into downloading crypto-stealing malware.
Your email address will not be published. Required fields are markedmarked